Lucene search

K
ibmIBMB4C907687D224CB393731E28C65162102BC31DF33FBD8662434019313B2A5800
HistoryJun 16, 2018 - 8:05 p.m.

Security Bulletin: IBM WebSphere Dashboard Framework is affected by a security vulnerability in Apache POIย (CVE-2016-5000)

2018-06-1620:05:10
www.ibm.com
8

0.006 Low

EPSS

Percentile

79.3%

Summary

Apache POI, which is bundled with IBM WebSphere Dashboard Framework, could allow a remote attacker to obtain sensitive information.

Vulnerability Details

IBM WebSphere Dashboard Framework (WDF) bundles a copy of Apache POI, which is used by the spreadsheet integration functionality.

CVEID: CVE-2016-5000**
DESCRIPTION:** Apache POI could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error when XLSX2CSV example uses Javaโ€™s XML components to parse OpenXML files. An attacker could exploit this vulnerability using an XML document containing an external entity reference to read arbitrary files on the system.
CVSS Base Score: 4.3
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/115530&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)

Affected Products and Versions

WebSphere Dashboard Framework 7.0.1

Remediation/Fixes

_
Product_

|
_ VRMF_|
_ APAR _|

โ€”|โ€”|โ€”|โ€”
WebSphere Dashboard Framework| 7.0.1| LO90165| Download the fix

Workarounds and Mitigations

None

CPENameOperatorVersion
websphere dashboard frameworkeq7.0.1

0.006 Low

EPSS

Percentile

79.3%

Related for B4C907687D224CB393731E28C65162102BC31DF33FBD8662434019313B2A5800